SOHWC RFP Attachment X SOO_v4_05202021.pdf
PDF 398 KB Posted
- Attached to
- 2021 eSafety Recompete Federal contract opportunity
- Solicitation number
- 12760421Q0122
- Issued by
- Department of Agriculture Forest Service
About this file
This statement of objectives describes requirements for an integrated occupational safety and health and workers' compensation case management software as a service solution. Key requirements include an incident and injury reporting system integrated with electronic claims filing for the Department of Labor. The solution must support all Forest Service employees and scale to additional USDA agencies. It should provide data migration from an existing system, identity management integration, and electronic data interfaces for payroll, travel, and customer relationship management systems. The proposed period of performance is a one year base period and four one-year options. The solicitation seeks a transition plan and identifies performance standards for system availability and integration completion. The document provides context on federal workers' compensation programs and the Forest Service workload.
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF OBJECTIVES
(SOO)
Department of Agriculture, Forest Service (FS)
For Providing Software as a Service (SaaS) for Reporting Incidents of Work Related Accidents, Injuries, Illnesses and Safety Stories and for Performing Workers’ Compensation (WC) Case Management
May 2021
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 2 of 19
Table of Contents
1 PROJECT BACKGROUND
2 STATEMENT OF OBJECTIVES
2.1 Guiding Principles
3 OBJECTIVES AND GOALS
3.1 Continuity of Services
3.2 Transition Strategy
3.3 Continuity of Operations (COOP)/Disaster Recovery
3.4 Management Approach
4 PERIOD OF PERFORMANCE
4.1 System Integrations
5 PLACE OF PERFORMANCE
6 TRAVEL
7 GOVERNMENT FURNISHED INFORMATION (GFI)
8 DELIVERABLES
9 PERFORMANCE STANDARDS
10 POINTS OF CONTACT
11 SECURITY REQUIREMENTS
11.1 Privacy Act
12 APPLICABLE DOCUMENTS
13 LIST OF APPENDICES
14 IT Security Language…………………………………………………………………… 14
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 3 of 19
1 Project Background
Each year, Federal civilian employees sustain work-related injuries and illnesses. In 2018, Federal workers filed almost 107,000 new claims and received approximately $3 billion in workers' compensation payments. Many of these work-related injuries and illnesses are preventable, and executive departments and agencies can and should do more to improve workplace safety and health, improve efficiencies, reduce the financial burden of injury on taxpayers, and relieve unnecessary suffering by workers and their families.
Therefore, the Protecting Employees, Enabling Reemployment (PEER) Initiative was created to set forth goals to achieve these important objectives and supports the President' s Management Agenda -Modernizing Government for the 21st Century and the President's Initiative to Stop Opioid Abuse and Reduce Drug Supply and Demand. Federal agencies including the US Forest Service are expected to improve or maintain performance in seven areas:
1 Reducing total injury and illness case rates;
2 Reducing lost-time injury and illness case rates;
3 Increasing the timely filing rate for workers' compensation claims;
4 Increasing the timely filing rate for wage-loss claims;
5 Increasing the rate of return-to-work outcomes during the initial 45 day post-injury period for traumatic injury cases;
6 Improving the rate at which employees return to work in cases of moderate to severe injury or illness;
7 Implementing and fully using the Department of Labor's electronic filing system.
In 2013, the FS awarded a contract to Origami Risk to provide an integrated solution with electronic means to report safety and health incidents, accidents and near-misses, and to file CA- 1 and CA-2 forms for workers compensation (WC) with DOL, as required per 20 Code of Federal Regulations (CFR)10.100. The acquisition was conducted via a full and open competition. The contract was firm fixed priced with a four month base/transition period, five 12-month option periods and a one year Bridge.
The solution, given the name “eSafety,” was initially hosted at Amazon Web Services (AWS) East/West hosting environment, as selected by the vendor, but was migrated in 2016 to an alternative FedRamp-certified authorized hosting environment, AWS GovCloud, which met the more stringent IT Security needs as preferred by FS and USDA OCIO at that time. A contract modification was approved to cover the one-time expense to migrate the data to the new environment.
When an Employee has been injured or made ill at work, a claim is filed with the DOL Office of Workers’ Compensation Program (OWCP). This claim is completed by the Employee and his/her Supervisor/Case Manager. The means by which this claim is submitted and tracked is handled differently across the USDA Agencies. Some have limited tools to assist with this
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 4 of 19 process; some use manual processes and other Agencies have outsourced. The Employee’s direct compensation is handled by OWCP once the claim is received. OWCP and the USDA Supervisor/Case Manager will work together on returning that injured worker to suitable employment, if possible. OWCP will then send chargeback reports to the Safety and Health Management Division (SHMD) of USDA. Chargeback reports are the list of ongoing WC claims that OWCP has paid out, being billed back to USDA. The SHMD’s responsibility is to then take these chargeback reports, separate them by Agency/Unit and tie them back to the original injury incident and disseminate it back to the Agency/Unit. Currently, there is no system that allows this process to be done in an efficient manner.
The contractor’s solution would address the environment and challenges noted above. This system would be used for reporting, tracking, invoicing and recordkeeping from the point of incident to the closure of any claim associated with the incident. The system must be capable of handling the current FS case load.
FS spends an average of about $23 million per year in medical and compensation payments for Employees that were injured or made ill at work. As of the end of FY2018, there were over 5,000 active WC claims reported, with 2,558 of those as new cases in 2017. In addition, FS maintains a database of incidents/claims spanning over the years in excess of 50,000 records which will need to be migrated to any new solution to allow for tracking and reporting across all data.
USDA is embarking on a process to procure an integrated OSOH/WC solution and achieve improved performance as detailed in the PEER Initiative guidelines. In addition, USDA’s OSOH/WC Enterprise Solution Project seeks to deliver a common OSOH/WC footprint to be utilized by all USDA entities: Department, Mission Areas, Offices and Agencies (henceforth referred to as “Agencies”). The business requirements will:
Govern USDA OSOH/WC operational standards and processes Ensure compliance with current Service Level Agreements (SLAs) Dictate the best Information Technology (IT) solution
2 Statement of Objectives
The US Department of Agriculture (USDA), Forest Service (FS) is seeking a vendor to provide an information technology solution, including continuing support, hosting and operations, through Software-as-a-Service (SaaS) licenses, to deliver an integrated incident reporting and workers compensation case management software solution that supports both Safety and Workers Compensation staffs to process and track actions. The solution must support all FS employees, including temporary and volunteer employees, and Human Resources (HR) and Safety team staff within FS locations of oversight (including National Forest work locations).
It is the intention of FS to immediately transition to the services provided by the successful Offeror.
It is the intention of the Government to provide interested vendors with the Government’s high-level objectives and requirements in this document. Offerors should respond with a proposed
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 5 of 19
Performance Work Statement (PWS) that details their approach and contractual requirements in meeting the Government’s objectives. This PWS will form the basis of a future contract with the successful offeror.
2.1 Guiding Principles
In selection of a vendor solution, the Government will be guided by the following principles:
USDA and Agency access to safety, occupational health and WC data improves its ability to reduce the risk of illness and injury and return Employees back to work and lower overall costs.
The efficiency, effectiveness and compliance of USDA and Agency efforts are improved through the common framework (e.g., a single, unified system) for managing safety, occupational health and WC cases.
USDA meets the requirements of the PEER initiative through improved Leadership actions as a result of the data and reporting capabilities of the tool.
A widely used and positively viewed solution as a result of user-friendly and actionable solution.
Manual filing of claims will be eliminated and replaced by the solution, and the speed for filing claims will increase for Agencies currently using manual processes.
A seamless transition from existing systems/processes to the contractor’s system.
3 Objectives and Goals
FS seeks to contract with a SaaS solution provider for meeting its OSOH incident tracking and reporting, and WC case management needs. The selected solution, however, must provide for contract expansion to include USDA and Land Management Agencies if they buy-in.
Specifically, the Government’s objectives are to contract for a solution that:
1. Supports the goal of the Department to identify the causes and reduce the risk of injuries and/or illnesses on USDA properties and to closely monitor the WC benefit program to reduce/eliminate erroneous and/or fraudulent payments and to return individuals to productive work status resulting in significant cost savings to the Government;
2. Is a mature product based on a Commercial Off-The-Shelf (COTS) software that will require minimal customization to meet all/most of the needs of the Government’s standard platform of mandatory and critical requirements as defined in Appendix C (“Integrated Requirements with Response Matrix”) (functionality or innovations that exceed the specified requirements should be highlighted in the vendor’s proposal of services);
3. Is scalable to accommodate USDA Agencies;
4. Includes a robust user experience to simplify input and use by a wide range of users, including help features to assist users in completing forms, etc., (e.g., mouse-over context, sensitive help aides), robust system performance to a geographically-dispersed user community and limitation on the need to enter redundant information (i.e., enter once, use many);
5. Is able to accommodate access to users for self-reporting incidents who are USDA Employees, including new Employees that may not have records in the system of record yet, Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 6 of 19 as well as Temporary, Administratively Determined (AD) or Casual Hire Employees, volunteers and employees of other Government Agencies and Departments;
6. Fully supports the objectives of OSHA standards.
7. Has robust reporting and dashboard capabilities, including user-initiated ad-hoc and standard reporting tools (e.g., drag-and-drop field level reports), saved reporting templates, trending, analytics, and executive/management dashboard reporting;
8. Has robust records management capabilities for search and retrieval of active, as well as archived/restored records, to meet records requirements (e.g., Freedom of Information Act (FOIA) requests, audits, litigation support);
9. Accommodates the need to migrate existing data into the solution for comprehensive reporting, trending analyses and research continuity;
10. Provides bi-directional transmission of claims data to include filing claims for such forms as the CA-1 and CA-2 as integrated with the Government’s operational EDI with the DOL. The solution must add new forms and delete obsolete forms per OWCP:
(https://www.dol.gov/agencies/owcp/dfec/regs/compliance/forms)
11. Is compliant with, and maintains compliancy with all Government regulatory authorities, including DOL’s Occupational Health and Safety Administration (OSHA) and OWCP requirements. The solution should evolve in line with other software improvements in the marketplace, as well as changing DOL and Federal Employees Compensation Act (FECA) requirements;
12. Provides OSOH and WC Program Users with system alerts (e.g., dashboard notifications, customized end user portal pages, email notifications) for such things as new claims filed, updates to claims, Continuation of Pay (COP) notifications, required medical follow-up, case status changes for WC claims, or investigations processes alerts, facility inspections, safety program evaluations, OSHA 300 tracking updates for safety incident reporting;
13. Includes robust training tools, such as Computer Based Training (CBT) for various levels of system users, to be updated as needed to maintain currency and provide on-site training to WC staff of a minimum of 40 hours;
14. Must have the capability to support multiple Agencies in the circumstance where WC case management is outsourced to a customer (e.g., where FS is processing WC claims for another Agency within USDA);
15. Must have the capability for the WC supervisor to assign claims processing regardless of region/forest serviced;
16. CA-7’s can be completed in incident reporting with automatic interface to DOL;
17. Capable of automatically generating OSHA reports; and
18. Can be integrated with the Department’s SSO authentication solution, currently hosted by
GDC Integration, Inc. (GDCI), the Department’s EDI with the DOL, also currently hosted by GDCI and other specified integration points;
19. The system must be capable of handling the current FS case load, as well as scalable for potential future implementations to accommodate caseload of USDA;
In addition, the Government’s objectives are to contract with an offeror that:
1. Provides ongoing Tier Three application help desk support, timely bug fixes/patches and a sound methodology for system enhancements (e.g., customer feedback analysis, customer requested product enhancements);
https://www.dol.gov/agencies/owcp/dfec/regs/compliance/forms
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 7 of 19
2. Provides the required compliance with the Government FedRAMP security, privacy and accessibility requirements, including support throughout the certification processes and continued re-certification, as required;
3. Provides robust Disaster Recovery/Continuity of Operations capabilities;
4. The Government maintains full ownership and unlimited data rights to all data and related material entered in the solution, either through direct data entry or through migration/uploading of data;
5. Provides a robust program management approach and resources to support program activities and reporting requirements; and
6. Proposes a strategy that is advantageous to the Government for both transition in and transition out of contract activities, including provision of all Government data periodically and at the end of the contract period in a commercially acceptable format as agreed to by the Government.
3.1 Continuity of Services
(a) The Contractor recognizes that the services under this contract are vital to the Government and must be continued without interruption. Upon eventual contract expiration, with a bridge or a new successor, services may continue. If a successor is to be used, then due diligence will be done to award a new contract prior to the old one expiring. The Contractor agrees to (1) furnish phase-in training and (2) exercise its best efforts and cooperation to affect an orderly and efficient transition to a successor.
(b) The Contractor shall, upon the Contracting Officer's written notice, (1) furnish phase-in, phase-out services for up to 90 days after this contract expires and (2) negotiate in good faith a plan with a successor to determine the nature and extent of phase-in, phase-out services required.
The plan shall specify a training program and a date for transferring responsibilities for each division of work described in the plan and shall be subject to the Contracting Officer's approval.
The Contractor shall provide sufficient experienced personnel during the phase-in, phase-out period to ensure that the services called for by this contract are maintained at the required level of proficiency.
(c) The Contractor shall allow as many personnel as practicable to remain on the job to help the successor maintain the continuity and consistency of the services required by this contract. The Contractor also shall disclose necessary personnel records and allow the successor to conduct on-site interviews with these employees. If selected employees are agreeable to the change, the Contractor shall release them at a mutually agreeable date and negotiate transfer of their earned fringe benefits to the successor.
(d) The Contractor shall be reimbursed for all reasonable phase-in, phase-out costs (i.e., costs incurred within the agreed period after contract expiration that result from phase-in, phase-out operations) and a fee (profit) not to exceed a pro rata portion of the fee (profit) under this contract.
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 8 of 19
3.2 Transition Strategy
The contractor should propose their approach to ensure a successful transition to their solution to include, but not be limited to, a proposed timeline, staffing, material or support required of the Government or vendors reporting to the Government, system integrations and data migration approach.
The Transition Strategy should include detailed information, to:
1. Coordinate with the FS and current contractor to define transition activities
2. Finalize a Transition Plan within five business days of the kick-off meeting. At a minimum, the Transition Plan should include:
a) Schedule and milestones
b) Roles and responsibilities
c) Approach and processes for transitioning data from the current solution to the contractor’s solution
d) A list of all Government dependencies and assumptions for Government services to be used during the transition
e) Transition risks and risk mitigation strategies
3. Coordinate and collaborate with the current contractor to transition efforts
4. Participate in ongoing transition planning calls, as determined by the contractor. If schedules and milestones slip, the Government may require more frequent meetings/calls.
5. Participate in weekly progress review meetings
6. Complete the transition and assume control and management of the work described in the
PWS within 120 days of contract award.
In addition, at the end of the contract, the contractor should propose a strategy to collaborate with the new contractor to successfully complete a seamless transition within the Government’s desired timeframe. This includes making data from the contractor’s solution available in standard formats, such as Comma Separated Values (CSV), Extensible Markup Language (XML), etc., as approved by the Government.
3.3 Continuity of Operations (COOP)/Disaster Recovery
The contractor should propose their approach to maintaining access to the solution once in the production environment including, but not limited to, system performance standards, data backup/restore, COOP and disaster recovery capabilities and strategy. The proposed strategy should include that, in the event of a COOP or disaster recovery event, the contractor will facilitate and manage a coordinated effort with the Government to track the event and its impact, and bring services back online as soon as feasible. An assessment of the impact and proposed mitigation strategies should be provided to the Government.
3.4 Management Approach
The contractor should describe their approach to software development and/or system life cycle standards and methodologies and ongoing management and financial reporting to the Government. In addition, the contractor should identify a proposed Staffing Plan for successful
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 9 of 19 transition, as well as ongoing operations and maintenance of the solution, to include identification of any Government resources required by the contractor.
4 Period of Performance
It is anticipated that a resulting contract will be for a base year (12 full calendar months), beginning on the date of award, inclusive of transition period,with four one-year option periods, to be exercised at the discretion of the Government, based on performance and funds availability.
4.1 System Integrations
The selected solution will need to establish several interfaces, which are detailed in this SOO and in Appendix C (“Integrated Requirements with Response Matrix”). In integrating with other systems, the contractor shall develop an Integration Plan that includes a detailed baseline budget and schedule. The contractor shall include and perform all customary tasks for integration to include planning, testing and other quality assurance tasks. The contractor shall provide verbal and written updates on integration progress, as requested for each integration project, as well as updates to the Integration Plan as requested by the Government. The following information is provided to support a common understanding of mandatory and critical interface requirements.
Referencing Requirement Integrated Project Solution (IPS)-147, the ConnectHR system is an SSO Internet Web portal that implements a common user interface (i.e., Dashboard) to Human Resource (HR) applications and data for FS Employees. ConnectHR has been designed to FS specifications and is hosted by GDC Integration, Inc. (GDCI) from their corporate data center in St. Louis, Missouri. Access is provided by GDCI to USDA Employees on an annual subscription basis, through the USDA e-Authentication process. While the GDCI Dashboard provides a secure SSO and user authentication capability for FS Employees, it will redirect requests for information or services to other appropriate commercial or Government service providers for execution. When a user request is passed through the Dashboard, it may be populated with additional information from the Employee’s personnel record, which is stored in the Dashboard database.
The selected solution must establish an Application Program Interface (API) with the GDCII Dashboard, which can provide user authentication with different levels of access to support application security requirements. All data transactions between the selected solution and GDCI will be performed using the proprietary GDCI standard Single Sign-on Server (SSS) API.
Implementation of the API is described in the attached document, GDCI Integration, Inc., HRLINK$ Technical Document Application Integration Using SSS API (Appendix D, “Single Sign On (SSO) API Specifications”).
Referencing requirement IPS-144 and IPS-144.1, the EDI port with the DOL has already been established and tested as part of the ConnectHR system. Pre-defined standard data fields will be transferred between the selected solution and the DOL Data Repository (DDR) API using industry standard Web Services Description Language (WSDL) and XML to communicate.
Referencing requirement IPS-144.2-7, the selected solution will also establish an EDI feed for receiving standard HR data and fields (e.g., from National Finance Center (NFC) EmpowHR), Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 10 of 19 including Employee first name, last name, Social Security Number, date of birth, etc. The selected solution will also establish an EDI feed for receiving Time and Attendance information.
This data will be utilized to validate against claims for compensation, leave buyback, etc. Both of these EDI feeds will be uploaded biweekly via flat file, File Transfer Protocol (FTP), API or other Web services. The selected solution will also establish an inbound EDI feed with GovTrip in order to validate information used in motor vehicle accident investigations. Real time Web services will trigger the need for data upload, which will occur nightly via flat file, FTP, API or other Web services.
Referencing requirement IPS 145 and IPS-146, the selected solution will also provide bi-directional EDI capabilities with the Customer Relations Management (CRM), a standard Oracle application, which will allow OSOH/WC incident and claim information to be tied to customer records. Information will be transferred via a nightly feed.
5 Place of Performance
The place of performance is the contractor’s normal place of business. The contractor will be expected to occasionally attend meetings, generally in the greater Washington, D.C. area or Albuquerque, New Mexico.
6 Travel
If travel is required, the Contracting Officer’s Representative (COR) with concurrence of the Contracting Officer shall approve all travel in advance of the contractor incurring any costs. The COR reserves the right to approve the number of contractor staff traveling. If required, travel will be reimbursed in accordance with the Federal Travel Regulation (FTR).
7 Government Furnished Information (GFI)
In order to maintain a complete record of data for purposes of reporting, tracking and management, it is essential for the solution provider to successfully migrate existing data from the Government’s current solution into the successor solution. Appendix E (“Current Database Field Descriptions”) details the data fields contained in the current database that will require migration. This Appendix provides examples of the current data structure and is not an inclusive list. The Government has approximately seven years of data with an excess of 50,000 records from the existing OSOH Incident Reporting system. The use of Non-Disclosure Agreements (NDA) will be used and maintained by the Contracting Officer.
In addition, the Government will provide the contractor with other material supporting compliance activities around IT Security Accreditation, Privacy Act compliance and Section 508 compliance, as needed.
All Government Furnished Information (GFI) will remain the sole property of the Government and will be returned to the Government in its entirety within 30 days of the close of the contract period or extension thereto.
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 11 of 19
8 Deliverables
The contractor shall submit all deliverables to the CO via email. Electronic copies shall be delivered using Microsoft (MS) Office® Suite tools (i.e., Word, Excel®, PowerPoint®, Access®, Project), unless otherwise specified by the CO.
The COR will have ten workdays to review draft deliverables and make comments. The contractor will have five workdays to make corrections. Upon receipt of the final deliverables, the COR will have five workdays for final review prior to acceptance or providing documented reasons for non-acceptance. Should the Government fail to complete the review within the review period, the deliverable will become acceptable by default.
The COR will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the contractor’s accepted proposal.
In the event of a rejected deliverable, the contractor will be notified in writing by the COR of the specific reasons for rejection. The contractor shall have five workdays to correct the rejected deliverable and return it per delivery instructions. Upon final acceptance of all deliverables, a final copy will be forwarded to the Contracting Officer for the file.
Table 1. Deliverables and Due Date
Deliverables Due Date Project Management Plan Within 30 days of contract award Risk Management Plan Within 30 days of contract award Transition Plan, Approach and Roadmap Within 15 days of contract award Data Migration Plan Within 30 days of contract award Integration Plan Within five business days of notice to proceed from the Government on specific integration projects.
Final Transition Plan Within five business days of the kickoff meeting with the Government
Online Operating Manuals and Training (Webinars) Within 45 days of contract award Financial and Management Status Report Within five business days of the last business day of the preceding month
9 Performance Standards
The offeror should propose performance standards to be monitored throughout the period of performance. The following are mandatory standards that must be addressed in the proposal, but the offeror should consider proposing additional performance standards as necessary to ensure acceptable performance:
Table 2. Performance Standards and Descriptions
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 12 of 19
Performance Standard
(PS) #
Performance Standards Acceptable Quality Level
(AQL)
Monitoring Method
PS-1 Contractor’s solution is available 24x7x365 to users.
Maintenance periods shall be communicated to the COR at least five days in advance.
Contractor’s solution is available 99% of the time, except during scheduled maintenance periods.
Feedback to COR on down-time by users and contractor-provided information.
PS-2 Integration with other Government systems is completed on-time and within a Firm Fixed Price, as submitted in the Integration Plan.
Integration is completed within five business days of the baseline schedule from the Integration Plan
Review by COR.
PS-3 A seamless transition is facilitated by the contractor in accordance with the Final Transition Plan and the approved schedule.
Transition is completed within five business days of the baseline schedule from the Final Transition Plan.
Review by COR.
10 Points of Contact
FS Contracting Officer (CO):
Melissa K. Paquin-Leon Contracting Officer
USDA FS
Washington Office (WO) Acquisition Management (AQM) IT Support Branch 4000 Masthead St NE Albuquerque, NM 87109 Phone: Email only E-mail: melissa.paquin-leon@usda.gov
FS COR:
Monica Moore Contracting Officer’s Representative
USDA FS
Chief Information Office 4000 Masthead St NE Albuquerque, NM 87109 Phone: Email only E-mail: monica.moore@usda.gov mailto:melissa.paquin-leon@usda.gov
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 13 of 19
11 Security Requirements
Work under this contract is Unclassified. All documentation (e.g., Department of Defense (DD)-
254) required for security certification will be the responsibility of the contractor and the client organization.
11.1 Privacy Act
Work on his project may require that personnel have access to Privacy Information. Personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable Agency rules and regulations. This includes, but is not limited to, participation in the preparation of a Privacy Impact Assessment.
12 Applicable Documents
1. DOL OWCP for FECA www.dol.gov/owcp/dfec/.
2. DOL OSHA www.osha.gov, including, but not limited to OSHA regulations for recordkeeping and reporting occupational injuries and illnesses (see Table of Contents/Authority for 29 CFR 1904 and 29 CFR 1960.70)
3. Technical Standards for Information Technology Accessibility Rehabilitation Act - Section 508 - 36 CFR Part 1194
4. 44 U.S.C. § 3541, “FISMA of 2002”
5. Federal Information Processing Standard (FIPS) Publication (PUB) 201, “Personal Identity
Verification of Federal Employees and Contractor/Solution Providers,” March 2006
6. OMB Circular A-130: Management of Federal Information Resources
7. FIPS PUB 140-2: Security Requirements for Cryptographic Modules
8. NIST Special Publications
9. HSPD-12
10. Privacy Act
13 List of Appendices
Appendix A—Acronyms Used in this Document: for reference purposes only; this document lists the acronyms that are used in the SOO and Appendices.
Appendix B—Standardized Business Processes: for reference purposes only; the standardized OSOH/WC functional business processes identify the high-level business processes that will be used for conducting activities involving the desired OSOH/WC solution.
**Appendix C—Integrated Requirements with Response Matrix: for response by offeror; FS OSOH/WC Requirements establish the business functions the solution must support. The matrix will provide an understanding of the system’s capabilities in relation to the OSOH/WC requirements. Complete the Fit Gap Status and return Appendix C with your Technical Proposal. It will be included in the review of your response.
http://www.dol.gov/owcp/dfec/ http://www.osha.gov/
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 14 of 19
Appendix D—SSO API Specifications: for reference purposes only; provides a common understanding of the interface specification created by GDCII, defining the API with the GDCII Dashboard.
Appendix E—Current Database Field Descriptions: for reference purposes only; this document provides examples of the data fields contained in the current database that will require migration.
Appendix F—Commonly Used Forms: for reference purposes only; the commonly-used forms used by the FS to document incidents, file compensation claims, report program metrics, etc.
Appendix G—WC Departmental Regulation(DR) 4430-003: for reference purposes only; this document sets forth the USDA policy and procedural guidelines on the Federal Employees Compensation Act (FECA), (Public Law 101-3, February 5, 1993) providing information on the reporting of and compensation for job-related injuries and occupational diseases.
Appendix H—OSOH DR 4410-004: for reference purposes only; this document establishes the USDA regulations and requirements for the Safety Management Program (SMP).
14 Security Language
1. SECURITY LANGUAGE FOR ALL CONTRACTS
It is the responsibility of both the agency and the procurement official to verify that this is in all contracts and agreements including the exercise of any contract options. Examples of tasks that require security provisions include acquisitions of IT hardware, software, applications, and systems, IT services, transmission or analysis of data owned by FS with significant replacement cost should the contractor’s and other external organization’s copy be corrupted.
Section 1 By accepting this contract/agreement, the Contractor/Cooperator and other external organizations (hereafter called Contractor) providing Information Technology (IT) resources or services to the US Forest Service (FS) agrees to comply with the applicable IT security policy as outlined in this document. The Contractor and other external organizations will be responsible for IT security for all systems connected to the FS network or operated by the Contractor and other external organizations for the FS, regardless of location. This clause is applicable to all or any part of the contract that includes IT resources or services in which the Contractor and other external organizations must have physical or electronic access to FS sensitive information that directly support the mission of the FS. The term “information technology,” as used in this clause, means any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information. This includes both major applications and general support systems as defined by OMB Circular A-130.
The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this task. The Contractor shall also protect all unclassified Government data, equipment, etc., by treating information as sensitive business, confidential information, controlling and limiting access to the information, and ensuring the data and equipment are secured within their facility.
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 15 of 19
The Contractor or other external organization will not publish or disclose in any manner, without the FS Contracting Officer’s written consent, the details of any programs, documentation, data, or safeguards either designed or developed by the Contractor or other external organization under this Contract or otherwise provided by the Government. The Contractor may be required to sign non-disclosure or other appropriate security agreements. A written agreement between the FS and any contractors and other external organizations will be entered into before FS data and information otherwise exempt from public disclosure may be disclosed to the contractors and other external organizations. The Contractor and other external organizations will agree to establish and follow security precautions considered by the FS to be necessary to ensure proper handling of data and information. As may be identified elsewhere in this contract, the Contractor agrees that:
• The draft and final deliverables and all associated working papers and other materials deemed relevant by the COTR that have been generated by the Contractor in the performance of this contract are the property of the U.S. Government and must be submitted to the COTR at the conclusion of the tasks.
• All documents produced for this project are the property of the U.S. Government and cannot be reproduced or retained by the Contractor.
To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor will afford the Government access to the Contractor’s or other external organization’s facilities, installations, technical capabilities, operations, documentation, records, and databases. The Contractor will cooperate with Federal agencies and their officially credentialed representatives during official inspections or investigations concerning the protection of FS information.
Cooperation may include providing relevant documentation showing proof of compliance with federal and agency requirements, and rendering other assistance as deemed necessary.
If new or unanticipated threats or hazards are discovered by either the Government or the Contractor or other external organization, or if existing safeguards have ceased to function, the discoverer will immediately bring the situation to the attention of the other party. The Contractor will report real or suspected incidents or violations immediately upon discovery to the FS Computer Incident Response Team (CIRT), by e-mail, at CIRT@fs.fed.us.
The Contractor shall insert these clauses in all subcontracts when the subcontractor is required to have routine physical access to a federally controlled facility and/or routine access to a federally controlled information system. Failure to comply with said requirements will constitute cause for termination.
The Contractor Agrees To –
(a) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies—
(i) The systems of records; and
(ii) The design, development, or operation work that the contractor is to perform;
(b) Include the Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and
(c) Include this clause, including this paragraph (3), in all subcontracts awarded under this contract that requires the design, development, or operation of such a system of records.
mailto:CIRT@fs.fed.us
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 16 of 19
In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.
Definitions of the clause:
(a) “Operation of a system of records,” as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.
(b) “Record,” as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person’s name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.
(c) “System of records on individuals,” as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
The contractors and other external organizations will ensure that the following banner is displayed on all FS systems that contain Privacy Act information operated by the contractors and other external organizations prior to allowing anyone access to the system:
“This system contains information protected under the provisions of the Privacy Act of 1974 (Public Law 93-579). Any privacy information displayed on the screen or printed must be protected from unauthorized disclosure. Employees who violate privacy safeguards may be subject to disciplinary actions, a fine of up to $5,000, or both.”
2. CONTRACTORS/COOPERATORS REQUIRE BUILDING ACCESS AND/OR
INFORMATION SYSTEM ACCESS
It is the responsibility of both the agency and the procurement official to verify that this section is in all contracts/agreements including the exercise of any contract options where contractors/cooperators/volunteers will be accessing FS systems. Federal guidance and the FS require a background investigation on all Federal and non-federal personnel that is commensurate with their position, level of access, and need-to-know. (ref. Departmental Manual 3800: Common Identification Standard for U.S. Department of Agriculture Employees and Contractors and AGAR Advisory 81: Common Identification Standard for Contractors)
Section 2 IT Security Training: The Contractor and other external organizations will ensure that its employees performing under this contract fulfill all Forest Service requirements for mandatory security awareness and role-based advanced security training in accordance with OMB Circular A-130, FISMA, and NIST requirements, and sign all applicable FS statements of responsibilities.
Background Investigations: All non-government employees with unescorted access to FS facilities, computer systems and/or FS information must have background investigations
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 17 of 19 commensurate with the level of risk and magnitude of loss or harm. The FS will determine the level of background investigation and position classification needed.
Personal Identity Verification of Contractor Personnel: The Contractor shall be responsible for ensuring compliance by its employees with all applicable federal regulations, to include those of GSA, NIST, USDA, FS and HSPD-12. Contractors and their employees are subject to all Federal laws applicable to Government installations and are under the jurisdiction of the Federal Protective Service (FPS). The Contracting Officer Representatives (CORs; also known as Contracting Officer Technical Representatives), or other designated program/project officers, in conjunction with the FS HCM HSPD-12 staff, will assist the Contractor in processing the required Security Background Investigations/Clearances.
(1) The Contractor shall comply with the personal identity verification (PIV) policies and procedures established by U.S. Department of Agriculture (USDA) Directives 3800 series.
(2) Should the results of the PIV process require the exclusion of a Contractor’s employee, the Contracting Officer will notify the Contractor in writing.
(3) The Contractor must appoint a representative to manage this activity and to maintain a list of employees eligible for a USDA PIV ID Badge required for performance of the work.
(4) The responsibility of maintaining a sufficient workforce remains with the Contractor.
Employees may be barred by the Government from performance of the work should they be found ineligible or to have lost eligibility for a USDA PIV ID Badge. Failure to maintain a sufficient workforce of employees eligible for a USDA PIV ID Badge may be grounds for termination of the contract.
(5) The Contractor shall insert this clause in all subcontracts when the subcontractor is required to have access to a federally controlled facility or information system.
(6) The PIV Sponsor for this contract is the Contracting Officer Representative (COR), unless otherwise specified in this contract. The PIV Sponsor will be available to receive contractor identity information from * (hours and days) to * (hours and days) at * (office address for registration). The Government shall notify the Contractor if there is a change in the PIV Sponsor, the office address, or the office hours for registration.
(7) At this time, the Government will pay for and process all required security investigations/clearances, except as identified differently within this clause.
(8) The Contractor should be aware of any of its employees possibly having had a background investigation through another government agency. The investigation that was conducted, if verifiable by the FS HSPD-12 staff, and if it was completed within the last 5 years, can be accepted by the Government in lieu of a background check.
(9) The Contractor shall comply with any facility badging requirements for the issuance of building access, badges, etc.:
• Ensure that each of the Contractor’s employees has been issued either a temporary or permanent badge from the Government. A permanent badge will not be issued until the security questionnaire has been completed and favorably reviewed. Temporary or visitor badges will be provided for persons who are identified as having an infrequent or temporary legitimate business need for access to the site. As noted above, periods that exceed 180 days will require a permanent badge. The badge must be worn at all times while in the facility. It must be displayed above the waist. The individual will retain possession of the badge as long as continued admittance to the site is needed.
• Ensure the safekeeping, wearing, and visibility of Government-furnished badges.
• Immediately return all badges and permits to the Government when such need ceases to exist.
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 18 of 19
(10) The Contractor shall comply with any facility security requirements for access to the facility.
(11) The Contractor shall comply with all applicable rules governing parking at USDA locations.
3. ACQUIRING AND/OR IMPLEMENTING SOFTWARE APPLICATIONS
It is the responsibility of both the agency and the procurement official to verify that this section is in all new integration and application contracts including the exercise of any contract options.
(ref. USDA CIO letter June 2, 2008) Section 3 Secure Coding Skills: Contractor certifies that at least one member of each programming team working on any code (including C, Java, .Net, ASP.NET, Visual Basic) to be delivered to the Forest Service has earned the Global Information Assurance Certification for Secured Software Programming or equivalent.
Source code testing, binary code testing, application scanning, and penetration testing: At least one week prior to delivery of any code due under this contract, Contractor will deliver to the COTR the following reports covering all code that will be delivered:
A. Source code testing results showing all potential security flaws identified by at least one of the commercial source code testing tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor will highlight all vulnerabilities rated “critical” and “high.” The Contractor must then correct the vulnerabilities, resend the code, and ensure the health of delivered source code.
B. For web applications, web application scanning test results showing all potential security flaws identified by at least one of the commercial web application scanning tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor will highlight all vulnerabilities rated “critical” and “high.”
C. For all applications: application penetration results.
Copyright Management and Responsibility: By delivering applications or programming code to the Federal Government, the vendor or Contractor certifies that they have the proper authority to transfer the property and will defend the Government against copyright or other lawsuit resulting from the application or programming delivered.
4. ACQUIRING EXTERNAL IT SERVICES (PROCESSING, STORING, OR
TRANSMITTING FS DATA ON A NON-FS SYSTEM)
It is the responsibility of both the agency and the procurement official to verify that this section is in contracts including the exercise of any contract options on all external information systems or services. It includes external information systems or services provided by both government and non-government entities and applies to those services acquired in any manner by the FS, including those acquired by formal contract or by any other agreement (e.g., service bureaus, contractors, other service providers such as system development, network management, or security management).
Section 4 The Contractor or other external organizations will develop, provide, implement, and maintain an IT System Security Plan for any system that includes acquisition, transmission or analysis of data owned by FS with significant replacement cost should the Contractor’s and other external organization’s copy be corrupted. This plan will describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used
Request for Proposal (RFP) for Integrated OSOH/WC Case Management Solution Page 19 of 19 under this contract.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .